Datatilsynet (Denmark) - 09-07-2026 (Lyngby Boldklub)
Danish DPA permits football club to use facial recognition under strict conditions.
Summary
The Danish Data Protection Agency (Datatilsynet) has granted Lyngby Boldklub permission to use facial recognition technology during football matches. This authorization is conditional, requiring the club to adhere to specific retention periods, transparency measures, and objective enforcement of stadium regulations. The decision also mandates a data protection impact assessment and prior consultation if high risks are identified, emphasizing that GDPR and the Danish Data Protection Act apply where not superseded by these conditions.
Full text
Help Datatilsynet (Denmark) - 09-07-2026 (Lyngby Boldklub): Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 18:52, 1 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators44 editsmTag: Visual edit← Older edit Latest revision as of 13:09, 2 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators44 editsmTag: Visual edit Line 121: Line 121: == Comment ==== Comment == ''Share your comments here!''''Share your comments here!'' The same permission was granted to AC Horsens on the same day, see [[Datatilsynet (Denmark) - 09-07-2026 (AC Horsens)]]. == Further Resources ==== Further Resources == Latest revision as of 13:09, 2 September 2026 Datatilsynet - 09-07-2026 Authority: Datatilsynet (Denmark) Jurisdiction: Denmark Relevant Law: Article 9(1) GDPR Article 9(2)(g) GDPR Article 35 GDPR Article 36 GDPR Type: Other Outcome: n/a Started: Decided: Published: Fine: n/a Parties: Lyngby Boldklub National Case Number/Name: 09-07-2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Danish Original Source: Datatilsynet (in DA) Initial Contributor: sf The DPA granted a football club the permission to use facial recognition during their football matches. However, the authorisation is subject to conditions such as compliance with specific retention and transparency requirements. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial recognition during football matches to process biometric data. Processing such data would be done on the basis of Article 9(1) GDPR and Article 9(2)(g) GDPR, that is, necessary for reasons of public interest. Holding The DPA granted the controller authorisation to process biometric data with the use of automatic facial recognition for the purpose of uniquely identifying natural persons. The DPA granted the authorisation under a number of conditions, requires notification of any changes, and reserves the right to review them. The conditions include, inter alia: Authorisation only applies when the controller is in the Danish Super League. Suspensions from matches must be imposed on an objective and proportionate manner following a violation of the controller’s stadium regulations and/or the Super League's code of conduct. Personal data which does not concern an individual on the controller’s suspension list, persons of interest list or police’s suspension list may not be stored. Personal data which concern one of those persons must be deleted after every match. The DPA emphasised that the GDPR and the Data Protection Act apply to the extent that the issue at hand is not regulated by the above conditions. The DPA stressed that a data protection impact assessment must be performed in accordance with Article 35 GDPR. If it results in a high risk the controller must seek prior consultation under Article 36 GDPR. The DPA also maintained its position in handling complaints. The DPA further clarified that the use of images from the surveillance to be covered by the national CCTV Surveillance Act. The DPA declared the controller’s communication and enforcement of the suspension list as, necessary for the purpose of processing a specific dispute following the Danish CCTV Surveillance Act. The DPA thus permits the controller to store the stadium’s security camera footage for longer than 30 days. The DPA emphasises that retention of this footage for longer than 30 days imposes a subsequent obligation on the controller to inform the data subject visible in the footage and allow them to request a copy of such. Comment Share your comments here! The same permission was granted to AC Horsens on the same day, see Datatilsynet (Denmark) - 09-07-2026 (AC Horsens). Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Danish original. Please refer to the Danish original for more details. Skip the main navigation Lyngby Boldklub Granted Permission to Use Automated Facial Recognition Date: July 9, 2026 Authorization: Private Companies Following an application from Lyngby Boldklub and AC Horsens, the Danish Data Protection Agency has granted authorization for the clubs to process biometric data and thereby use automatic facial recognition during soccer matches. The above processing involves the processing of biometric data covered by the prohibition in Article 9(1) of the General Data Protection Regulation. Pursuant to Article 9(2)(g) of the Regulation, the prohibition on the processing of sensitive information does not apply if the processing is necessary for reasons of substantial public interest. Pursuant to Section 7(4) of the Data Protection Act, the Danish Data Protection Agency must grant authorization for such processing when it is not carried out by a public authority. The Danish Data Protection Agency hereby grants LYNGBY BOLDKLUB A/S Authorization to process biometric data pursuant to Section 7(4) of the Data Protection Act through the use of automated facial recognition at the LYNGBY BOLDKLUB A/S stadium Authorization to process biometric data for the purpose of uniquely identifying a natural person, through the use of automated facial recognition, is granted under the following conditions: This authorization applies only when LYNGBY BOLDKLUB A/S is the sole data controller for the processing of personal data with respect to the CCTV surveillance and the facial recognition system. This authorization applies only when LYNGBY BOLDKLUB A/S is a member of the Superliga. In this context, the authorization applies to the conduct of soccer matches, including friendly matches, involving teams from the Superliga, the 1st and 2nd divisions, as well as soccer matches organized by UEFA. The imposition of a ban must be based on objective and proportionate grounds in relation to the violation committed of LYNGBY BOLDKLUB A/S’s stadium regulations and/or the Superliga’s rules of conduct. Personal data processed as part of the facial recognition system that does not result in a match with information derived from 1) LYNGBY BOLDKLUB A/S’s ban list and/or watchlist or 2) the police’s general ban list, may not be stored. Personal data processed as part of the facial recognition system that results in a match with information derived from 1) LYNGBY BOLDKLUB A/S’s quarantine list and/or watchlist or 2) the police’s general quarantine list must be deleted immediately after each match. LYNGBY BOLDKLUB A/S must comply with the duty to provide information when collecting personal data. LYNGBY BOLDKLUB A/S must also, through signage or other clear means, provide information that access control is being conducted, including the processing of biometric data using an automated facial recognition system. Personal data processed as part of the facial recognition system must be transmitted to and stored in encrypted form on the server using up-to-date and widely recognized encryption algorithms. Surveillance cameras must be installed on a separate VLAN and must not be exposed to the internet. LYNGBY BOLDKLUB A/S must implement access control using the facial recognition system, including ensuring that employees are authorized to operate the facial recognition software and logging manual lookups during the login process. Use of multi-factor authentication in the login process. 10. Any changes to the conditions covered by this authorization must be reported to the Danish Data Protection Agency. The above terms apply until further notice. The Danish Data Protection Agency reserves the right to review these terms should the